cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3377
Views
0
Helpful
1
Replies

Source fire integration with QRADAR

hardeepsinghcs
Level 1
Level 1

Hello. I’m trying to configure sending event logs from Sourcefire DC to IBM Security QRadar SIEM using the eStreamer API Service. There is information from IBM documentation: I must download and install one of the following hotfixes from the Sourcefire website to collect Sourcefire Defense Center 5.x events in QRadar: – Sourcfire_hotfix-v5.1.0-0-build_1.tar – Sourcfire_hotfix-v5.1.1-0-build_1.tar

Could you please tell me where can I find these hotfixes? The second question: I have installed Sourcefire v 5.3.1 (build 152). Is there hotfix for this version?

1 Reply 1

atatistc
Cisco Employee
Cisco Employee

You probably already figure this out...  The hotfixes you're referring to were for the 5.1x version.  Since you're now at 5.3x they would not be needed.

Review Cisco Networking for a $25 gift card